From 33cb8d987d3b2543378408b227a4a63eec4f150b Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Fri, 9 Oct 2026 07:44:53 -0500 Subject: [PATCH] pass only the request path in X-Original-URL (#24602) nginx built X-Original-URL from the client's Host header plus the request path, so a Host containing '#' or '?' pushed the real path into the URL fragment or query. The media and go2rtc auth checks then saw an empty path and allowed restricted-role users to read other cameras' clips, recordings, exports and live streams. The header now carries only $request_uri, which is all the auth checks need. --- docker/main/rootfs/usr/local/nginx/conf/auth_location.conf | 2 +- docker/main/rootfs/usr/local/nginx/conf/proxy.conf | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docker/main/rootfs/usr/local/nginx/conf/auth_location.conf b/docker/main/rootfs/usr/local/nginx/conf/auth_location.conf index 285a3d81b0..619a2b3ff1 100644 --- a/docker/main/rootfs/usr/local/nginx/conf/auth_location.conf +++ b/docker/main/rootfs/usr/local/nginx/conf/auth_location.conf @@ -14,7 +14,7 @@ location /auth { proxy_pass_request_headers off; # Pass info about the request proxy_set_header X-Original-Method $request_method; - proxy_set_header X-Original-URL $scheme://$http_host$request_uri; + proxy_set_header X-Original-URL $request_uri; proxy_set_header X-Server-Port $server_port; proxy_set_header Content-Length ""; # Pass along auth related info diff --git a/docker/main/rootfs/usr/local/nginx/conf/proxy.conf b/docker/main/rootfs/usr/local/nginx/conf/proxy.conf index a3aacc3095..7ab5b58d15 100644 --- a/docker/main/rootfs/usr/local/nginx/conf/proxy.conf +++ b/docker/main/rootfs/usr/local/nginx/conf/proxy.conf @@ -2,7 +2,7 @@ proxy_set_header Host $host; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; -proxy_set_header X-Original-URL $scheme://$http_host$request_uri; +proxy_set_header X-Original-URL $request_uri; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Host $http_host; proxy_set_header X-Forwarded-URI $request_uri;